Fake

Mal/FakeAV-UF removal

Malware Removal

The Mal/FakeAV-UF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/FakeAV-UF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Attempts to access Bitcoin/ALTCoin wallets
  • Touches a file containing cookies, possibly for information gathering
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/FakeAV-UF?


File Info:

name: 49F12F86E70FC7893C3A.mlw
path: /opt/CAPEv2/storage/binaries/7f719c7174b72a6dfe17ceb46b82496ee4f48430d642df1252ac5be61757b43f
crc32: 2E6E05A5
md5: 49f12f86e70fc7893c3af70bd13d8736
sha1: bb84b18d807b4988ed97cafa4f5976086ec6fc33
sha256: 7f719c7174b72a6dfe17ceb46b82496ee4f48430d642df1252ac5be61757b43f
sha512: f525848b727be9faa6e31d0d7c9bfe0a13b8e0f62908e4a2001d8f4fb7cd62bef237dcb50d62c6c5a214d33b91e4da843cf7408140c1558901e8a219ddd86f3d
ssdeep: 24576:MpcJourU5qJh3j7nWU9zz/4TOGO8O+to:MavHJ9j7Waz/IOGOL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17005235525E43E72FEE27276E4E0CB3D6A49CFA21508D0253A9D85F3618E22BF773142
sha3_384: ad89e1748a771dbea3f56bcedaadc716d6b87f340aa41a8e709405774f4b5d27acf2e184a79eb852346207b42ccbf70e
ep_bytes: 8d0c246681e900ff0f825800000068a8
timestamp: 2013-10-01 11:23:51

Version Info:

0: [No Data]

Mal/FakeAV-UF also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lKKk
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.49f12f86e70fc789
CAT-QuickHealTrojanPWS.Zbot.Gen
SkyhighBehavesLike.Win32.Trojan.cc
McAfeeGeneric-FANU!49F12F86E70F
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.764530
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f72a1 )
AlibabaVirTool:Win32/Obfuscator.f184de9a
K7GWTrojan ( 0040f72a1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36738.ZmX@a0t@byk
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BONO
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Hlux.csockw
AvastWin32:Downloader-UWY [Trj]
TACHYONBackdoor/W32.Hlux.841232.BJ
EmsisoftTrojan.VIZ.Gen.1 (B)
F-SecureBackdoor.BDS/Hlux.bwdpuob
DrWebBackDoor.SlymENT.2075
VIPRETrojan.VIZ.Gen.1
TrendMicroBKDR_KELIHOS.SMF
Trapminemalicious.high.ml.score
SophosMal/FakeAV-UF
SentinelOneStatic AI – Suspicious PE
GDataTrojan.VIZ.Gen.1
JiangminTrojan/Generic.bixwx
WebrootW32.Dropper.Gen
GoogleDetected
AviraBDS/Hlux.bwdpuob
Antiy-AVLTrojan[Backdoor]/Win32.Hlux
Kingsoftmalware.kb.b.992
XcitiumTrojWare.Win32.Kryptik.BLUM@55v7j4
ArcabitTrojan.VIZ.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Kelihos.F
AhnLab-V3Trojan/Win32.FakeAV.R92608
VBA32Trojan.FakeAV.01657
ALYacTrojan.VIZ.Gen.1
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.FFS
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_KELIHOS.SMF
RisingTrojan.Bagsu!8.3B1 (TFE:1:XEzBE9dhg1Q)
IkarusBackdoor.Win32.Hlux
MaxSecureTrojan.Malware.6757233.susgen
FortinetW32/Kelihos.BQGD!tr
AVGWin32:Downloader-UWY [Trj]
Cybereasonmalicious.d807b4
DeepInstinctMALICIOUS

How to remove Mal/FakeAV-UF?

Mal/FakeAV-UF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment